Wayne wrote:


Well...I think I was hacked last night (two systems involved were the router sys and a game sys that I use to download (all the other systems were shut down)). I shut them down and disconnected from the network, I'm going to hose them down and re install their os's (win 98 se and Mandrake 9.1) so I can't really give you the outputs. One of my problems is I don't really know what rules Firestarter loads by default. I was trusting to faith that they were "good enough", was having another issue that I was addressing via the ng comp.os.linux.security and had a couple of other people ask "what rules are you running?" at which point I realized I better find out.....but not in time.

So...I'm back to running a W2K sys (the one that was supposed to be my web
and game server :-(   ) with Norton's Internet Security (I actually loaded
it on ALL my windows systems) until I have more knowledge of setting up a
secure firewall on Linux.

Sooooo!!!! Can anyone point me to a good website or a good book (iptables
for dummies maybe....) to better understand what I need to do to set up a
secure firewall?



Okay, time for me to jump on my soapbox :-). Most Linux distributions, and most UNIX systems for that matter seem to ship system configurations out the door that are easy for people to get working on because they start alot of services. Each tcp/udp port that you have listening is a potential buffer overflow waiting to happen (read remote root exploit). Some UNIX applications (mySql ships without a passwd) are even stupid enough to ship with default userids/passwords, some routers and network switches have pulled this as well. The default configuration out the door should be that everything is turned off by default, and if a password needs to be set, it should be forced to be set at 1st boot by the user/administrator.

If you are going to run a server, ideally the only ports left open should be for the service you are making available, and you should be subscribed to the development mailing lists for the 'server' to know when you are vulnerable. The only port I leave open is ssh, but them I am paranoid and use both a router/firewall and iptables :-). Taking a step beyond this, a server which has multiple people accessing it shouldn't have a complete install image on it, in particular setuid programs should be limited. I once examined all security alerts for RedHat Linux announced in a year, and came to the conclusion that I could have ignored half of them if I was picky about what I installed.


Jim (climbing down off of his soapbox) Doherty



(oh well...back to reloading software....AAARRRRRGGGGHHHHH!!!!!)


_______________________________________________ mhvlug mailing list - http://mhvlug.org [EMAIL PROTECTED] http://lists.dague.net/mailman/listinfo/mhvlug






_______________________________________________
mhvlug mailing list - http://mhvlug.org
[EMAIL PROTECTED]
http://lists.dague.net/mailman/listinfo/mhvlug

Reply via email to